Cybersecurity Frameworks for Digital Financial Institutions

  • Authors

    • Vladimir Glushkov Director, Institute of Cybernetics, Ukraine. Author
    • Victor Glushkov Academician, Academy of Sciences of USSR, Ukraine. Author

    DOI:

    https://doi.org/10.67228/3071642X/IJCFDE-2024PII2Y4F

    Published 10-05-2024

  • Cybersecurity Framework, Digital Financial Institutions, Information Security, Risk Assessment, Zero Trust Architecture, Artificial Intelligence, Blockchain Security, Financial Cyber Risk, Regulatory Compliance, Cyber Resilience

    Issue

    Section

    Articles

    How to Cite

    Glushkov, V., & Glushkov, V. (2024). Cybersecurity Frameworks for Digital Financial Institutions. International Journal of Commerce, Finance and Digital Economy, 7(2), 01-18. https://doi.org/10.67228/3071642X/IJCFDE-2024PII2Y4F
  • Abstract

    Digital transformation has been a game-changer for financial institutions, driving the bank industry's evolution into a more real-time, cloud-based, mobile, and AI-enabled financial landscape. While all these technological developments have boosted operational efficiency and customer service, they have also created new opportunities for cyber criminals to attack financial organizations with powerful and sophisticated means like ransomware, phishing, insider threats, Advanced Persistent Threats (APTs), Distributed Denial-of-Service (DDoS) attacks, identity theft, and financial fraud. This has given rise to the need for extensive cyber security systems to be a strategic necessity and not a technical necessity. In this paper, the authors explore modern approaches to cybersecurity frameworks for digital financial institutions, reviewing methodologies for assessing risk, governance of security, regulatory compliance, and innovations like Artificial Intelligence, Machine Learning, Blockchain, and Zero Trust Architecture. The study provides an overview of existing cybersecurity frameworks such as the NIST Cybersecurity Framework, ISO/IEC 27001, COBIT and PCI DSS, along with financial regulatory frameworks. In addition, a conceptual framework is suggested for enhancing cyber-resilience based on continuous monitoring, threat intelligence, automated incident response, and adaptive security controls. The findings have shown that the combination of intelligent security solutions and a standardized governance model not only increases the resilience of the organisation, but also reduces cyber risks, facilitates compliance with regulatory requirements and safeguard the trust of customers. The proposed framework offers a scalable and proactive strategy for financial institutions to address the escalating cyber threats in the ever-engaging digital landscape.

  • References

    [1] National Institute of Standards and Technology, Framework for Improving Critical Infrastructure Cybersecurity, Version 2.0, Gaithersburg, MD, USA, 2024.

    [2] International Organization for Standardization and International Electrotechnical Commission, ISO/IEC 27001:2022 Information Security, Cybersecurity and Privacy Protection—Information Security Management Systems—Requirements, Geneva, Switzerland, 2022.

    [3] International Organization for Standardization and International Electrotechnical Commission, ISO/IEC 27005:2022 Information Security Risk Management, Geneva, Switzerland, 2022.

    [4] ISACA, COBIT 2019 Framework: Governance and Management Objectives, Schaumburg, IL, USA, 2019.

    [5] Payment Card Industry Security Standards Council, Payment Card Industry Data Security Standard (PCI DSS), Version 4.0.1, 2024.

    [6] John Kindervag, "Build Security Into Your Network's DNA: The Zero Trust Network Architecture," Forrester Research, Cambridge, MA, USA, 2010.

    [7] Stuart E. Madnick, "The Hidden Costs of Cybersecurity Breaches in Financial Services," MIT Sloan Management Review, vol. 63, no. 3, pp. 1–10, 2022.

    [8] European Union, General Data Protection Regulation (GDPR), Regulation (EU) 2016/679, Brussels, Belgium, 2016.

    [9] Cloud Security Alliance, Security Guidance for Critical Areas of Cloud Computing, Version 5.0, 2022.

    [10] Open Web Application Security Project, OWASP Top 10: The Ten Most Critical Web Application Security Risks, 2021.

    [11] Ross Anderson, Security Engineering: A Guide to Building Dependable Distributed Systems, 3rd ed. Hoboken, NJ, USA: Wiley, 2020.

    [12] William Stallings and Lawrie Brown, Computer Security: Principles and Practice, 5th ed. Hoboken, NJ, USA: Pearson, 2023.

    [13] Thomas R. Peltier, Information Security Risk Analysis, 3rd ed. Boca Raton, FL, USA: CRC Press, 2016.

    [14] ENISA, ENISA Threat Landscape 2024, Heraklion, Greece, 2024.

  • Downloads

Similar Articles

51-60 of 88

You may also start an advanced similarity search for this article.